Key Responsibilities
- Administer and maintain Microsoft Entra ID, including Conditional Access, Identity Protection and Access Governance.
- Implement, operate and continuously improve Privileged Identity Management (PIM) controls and privileged access reviews.
- Support the secure configuration and operation of Microsoft Azure and Microsoft 365.
- Implement and maintain Microsoft Defender security controls.
- Support security monitoring, threat investigation and incident response activities.
- Support vulnerability management, including identifying, prioritising and remediating security weaknesses.
- Support Power Platform governance, including Data Loss Prevention (DLP) policies, environment management and application reviews.
- Produce and maintain security standards, procedures, technical documentation and operational guidance.
- Work with Cyber Security, Architecture, Infrastructure and wider business teams to embed security requirements into projects and BAU activities.
Essential Experience
- Strong hands-on experience administering Microsoft Entra ID / Azure Active Directory.
- Good knowledge of Identity & Access Management (IAM) principles and controls.
- Experience implementing or supporting Conditional Access and access governance.
- Knowledge of RBAC and privileged access management.
- Experience investigating security alerts and supporting cyber security incident response.
- Good understanding of Azure security fundamentals and Microsoft security best practices.
- Experience supporting Microsoft 365 security and cloud-based services.
- Experience producing technical security documentation, standards and procedures.
- Strong stakeholder engagement and communication skills.
Desirable Experience
- Experience in any of the following would be advantageous:
- Microsoft Privileged Identity Management (PIM)
- Microsoft Defender for Endpoint
- Microsoft Defender for Office 365
- Microsoft Sentinel
- Microsoft Power Platform governance
- Data Loss Prevention (DLP)
- PowerShell administration or automation
- Cyber security frameworks including Cyber Essentials Plus, NIST or ISO 27001
- Microsoft certifications such as SC-300, SC-900, AZ-900, MS-900 or AZ-500